CVE-2008-6402
sofi_webgui < 0.6.3pre - Remote Code Execution via mod_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6402. PoCs published by dun.
AI-analyzed exploit summary This is a writeup describing a Remote File Inclusion (RFI) vulnerability in Sofi WebGui <= 0.6.3 PRE. The vulnerability exists in the modstart.php file due to improper sanitization of the mod_dir parameter, allowing remote file inclusion.
Description
PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mod_dir parameter.
Exploits (1)
This is a writeup describing a Remote File Inclusion (RFI) vulnerability in Sofi WebGui <= 0.6.3 PRE. The vulnerability exists in the modstart.php file due to improper sanitization of the mod_dir parameter, allowing remote file inclusion.